Fixed builCsp.ts

This commit is contained in:
2026-09-19 22:32:29 +02:00
parent 848b12ce5d
commit f126eacf8c
4 changed files with 8 additions and 2 deletions
+1 -1
View File
@@ -14,7 +14,7 @@ export type BuildCspArgs = {
/** YouTube embeds — adds youtube to frame-src. */ /** YouTube embeds — adds youtube to frame-src. */
youtube?: boolean; youtube?: boolean;
}; };
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'object-src' | 'script-src' | 'style-src'; type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'media-src' | 'object-src' | 'script-src' | 'style-src' | 'worker-src';
/** /**
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required * Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
* directives baked in, and opt-in sources for common third parties. Solves the * directives baked in, and opt-in sources for common third parties. Solves the
+2
View File
@@ -46,6 +46,7 @@
'data:', 'data:',
'blob:' 'blob:'
], ],
'media-src': [],
'script-src': [ 'script-src': [
"'self'", "'self'",
"'unsafe-inline'" "'unsafe-inline'"
@@ -55,6 +56,7 @@
"'unsafe-inline'", "'unsafe-inline'",
'https://fonts.googleapis.com' 'https://fonts.googleapis.com'
], ],
'worker-src': [],
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit: // HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
'base-uri': [ 'base-uri': [
"'self'" "'self'"
File diff suppressed because one or more lines are too long
+4
View File
@@ -24,9 +24,11 @@ type CspDirective =
| 'frame-ancestors' | 'frame-ancestors'
| 'frame-src' | 'frame-src'
| 'img-src' | 'img-src'
| 'media-src'
| 'object-src' | 'object-src'
| 'script-src' | 'script-src'
| 'style-src' | 'style-src'
| 'worker-src'
/** /**
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required * Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
@@ -64,8 +66,10 @@ export function buildCsp(args: BuildCspArgs = {}): { key: string; value: string
'form-action': ["'self'"], 'form-action': ["'self'"],
'frame-src': [], 'frame-src': [],
'img-src': ["'self'", 'data:', 'blob:'], 'img-src': ["'self'", 'data:', 'blob:'],
'media-src': [], // video/audio sources — filled via extra when needed
'script-src': ["'self'", "'unsafe-inline'"], 'script-src': ["'self'", "'unsafe-inline'"],
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'], 'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
'worker-src': [], // web workers — filled via extra when needed
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit: // HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
'base-uri': ["'self'"], // block <base> hijacking 'base-uri': ["'self'"], // block <base> hijacking
'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options) 'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options)